Purpose and who this notice covers
This notice applies when Coul collects, receives, organizes, displays, analyzes, summarizes, or stores information from a public creator, brand, business, professional, or other social profile. It protects both Coul users and people who have never opened an account.
Coul's competitor features are intended to help a creator select references, compare public facts, understand high-level trends and formats, and develop original ideas. They are not intended to create a searchable people directory, identify private individuals, reproduce another creator's work, or authorize content-level virality scoring of competitor videos.
The Privacy Policy explains Coul's broader data practices. This focused notice adds the source, field, provenance, AI-inference, retention, removal, platform, and copyright details most relevant to public-profile data.
Coul's controller role and identity
Coul is the controller and, where the statutory criteria apply, the business for its standardized public-profile collection, normalization, analytics, competitor intelligence, derived retrieval, source provenance, rights handling, and compliance. A customer's choice to follow a competitor does not make contract with that customer the ordinary legal basis for processing the non-user's personal data.
The controller is the Coul service operator identified in the Service and transaction record. Before launch, this notice must state that operator's verified legal name, geographic address, jurisdiction, monitored privacy contact, and any DPO or EU/UK representative that is actually appointed or legally required. No role or address should be invented.
Platforms, source links, and providers
The implemented competitor-refresh flow supports public Instagram, TikTok, and X profiles through Bright Data profile datasets. A Coul user selects a canonical public profile URL, and the provider can return the profile and associated public post information. Coul may add, suspend, or remove a source when permissions, product support, platform terms, or technical access changes.
Coul intends to obtain only information it is permitted to collect and use from approved public sources. A Bright Data subscription, a public URL, or the ability to view a post does not by itself prove that every platform authorizes automated collection, commercial analytics, derived use, retention, or onward disclosure.
The product's freshness target for a competitor refresh is currently 24 hours, but it is not a promise that every source is checked daily. Provider delay, rate limits, platform changes, a private account, deletion, login requirements, and other restrictions can prevent refresh.
Information Coul may receive or create
The exact fields depend on the platform, profile, post, provider response, and product configuration. A snapshot can contain normalized fields and provider-specific raw metric keys, so the following categories are illustrative rather than exhaustive.
Platform, canonical source URL, normalized handle, external identifier, display name, biography, avatar URL, verification status, account attributes, and public profile links.
Follower, following, post, like, view, comment, share, save, repost, and other public counts or calculated engagement rates.
Post and profile identifiers, source URL, caption, hashtag, mention, format, publication date, thumbnail or media reference, media type, dimensions, duration, and other public post metadata.
Provider request and snapshot identifiers, first-seen, last-seen, collected, refreshed, and source-observation dates, plus provenance and validation results.
Coul-derived summaries, content categories, hook or format patterns, comparisons, trend signals, post summaries, embeddings, relevance scores, and workspace-reference links.
Snapshots, provenance, and accuracy
Public-profile data is a snapshot, not a verified identity record or live platform feed. Counts can be estimated, sampled, delayed, manipulated, bot-influenced, later hidden, or removed. Verification badges, handles, names, and avatars can change; parody, fan, impersonation, and reassigned-handle accounts can be mistaken for an official source.
Coul preserves available source URL, platform, external identifier, collection or snapshot date, provider provenance, and first or last seen information so a record can be checked and disputed. On a verified request, Coul provides available source categories and origin information where law requires it.
A historic metric may be impossible to prove after the source changes. Coul should label a disputed or stale snapshot rather than silently represent it as current. Source attribution and a link improve provenance but do not establish accuracy, permission, endorsement, or a copyright defense.
Competitor intelligence, AI inference, and embeddings
For request-time competitor intelligence, Coul may send selected public profile and post information to the configured Gemini service. That context can include a handle, display name, biography, captions, hashtags, format, publication time, and public engagement metrics. Gemini may return high-level profile summaries, content categories, hook patterns, and post summaries.
Coul can embed those derived summaries in Qdrant for tenant-scoped retrieval, recommendations, and workspace memory. The implemented payload marks competitor material as public reference, prohibits direct copying, and prohibits competitor content from virality prediction. These internal labels are safeguards, not a license from a creator or platform.
Request-time inference and embedding for retrieval are not model training. Before launch, Coul must verify the deployed Gemini tier, contract, region, provider retention, and data-use controls; Coul does not promise that a provider never retains or trains on submitted data until those controls are verified and accurately disclosed.
Purposes and applicable legal bases
Coul uses public-profile information narrowly to surface user-selected inspiration, organize public facts, provide comparisons and analytics, identify high-level trends or format patterns, create non-copying summaries, support workspace retrieval and recommendations, maintain provenance, protect the Service, handle rights requests, and comply with law.
Where GDPR or UK GDPR applies, Coul ordinarily relies on a documented legitimate-interest assessment—not a customer contract or presumed consent—for processing non-user public data. The assessment must establish the specific purpose, necessity, and balance against the person's rights and reasonable expectations.
Factors include professional versus personal context, collection scale, refresh frequency, expected audience, caption/avatar/media use, derived inferences, commercial access, and less intrusive alternatives.
Coul must give extra weight to children, sensitive subjects, harassment or impersonation risk, private or deleted sources, source objections, and people who would not reasonably expect commercial creator-intelligence indexing.
Linking, official APIs, approved embeds, aggregation, shorter retention, limited fields, and excluding media can be less intrusive alternatives and should be preferred where they still meet the purpose.
Public access is not unrestricted permission
Publicly accessible and lawfully reusable are not synonyms. Platform terms, API or dataset licenses, robots and access controls, privacy law, database rights, copyright, contract, and source-specific deletion rules can all limit automated collection and use.
Before production collection, Coul must verify permission for Instagram, TikTok, X, and each future source separately, including the collecting entity, dataset, official API or written entitlement, fields, commercial purpose, derived analytics, storage, transfers, retention, deletion, and onward access. Provider representations do not replace Coul's own review.
Coul will stop or restrict a source when it cannot establish an appropriate permission and legal basis. Circumventing login, private, deleted, blocked, age-restricted, or other access controls is not an approved public-data source.
How competitor inspiration may—and may not—be used
Users may study factual public metrics and use ideas, themes, topics, general methods, and unprotected formats as inspiration for original work. They may not use Coul to reupload another creator's media, copy captions or scripts, reproduce protected expression, strip attribution or rights information, impersonate a creator, or imply endorsement, sponsorship, or affiliation.
Public content is not public domain. Creators and platforms retain applicable copyright, trademark, publicity, moral, database, and contractual rights. Fair use and fair dealing are jurisdiction- and fact-specific; source attribution or a link does not by itself cure infringement.
Competitor content is not eligible for Coul's virality analyzer or automatic editing merely because it appears in a feed. Only the user's own or otherwise authorized content may be submitted for scoring or editing, and the technical ownership gate described in the AI Transparency notice must be live before launch.
Providers, recipients, and transfers
Public-profile information can be disclosed to the Coul user or workspace that selected the source, authorized workspace members, Bright Data for collection, Gemini for request-time inference, configured database, object-storage, cache, logging, and Qdrant providers, professional advisers, and authorities or successors where legally required.
Coul does not make a non-user profile public merely by displaying it within authorized product features. A user can still export, screenshot, quote, or publish material outside Coul; Coul cannot always recall third-party or user-controlled copies, but the Terms and policies continue to restrict misuse.
Processing may occur outside the person's country. Before launch, Coul must publish deployed provider entities, locations, purposes, roles, and transfer mechanisms and verify that onward providers honor source restrictions and removal instructions. The Privacy Policy explains applicable safeguards.
Current model-training position
As of the effective date, Coul does not use profile-linked public identifiers, media, captions, or embeddings to train a shared, general-purpose, generative, or Coul prediction model. Public information may be used at request time for competitor-intelligence inference, and derived summaries may be embedded for tenant-scoped retrieval.
Coul may use genuinely aggregated or deidentified performance statistics and deliberately contributed evaluation examples for quality or calibration. Hashed, pseudonymized, or embedded profile-linked data is not treated as anonymous merely because a direct name is absent.
Coul will update this notice, identify an applicable legal basis, complete required assessments, and provide any legally required choice before beginning a materially different training use. The Privacy Policy contains the same current position and controls if the descriptions diverge.
Retention, refreshes, and stale sources
Raw Bright Data result artifacts are retained for 90 days by default; production configuration can shorten that period to no less than 30 days. A complete time-based period for normalized profiles, posts, snapshots, derived summaries, embeddings, caches, audits, and backups has not yet been approved and must be set before launch.
Normalized records should remain only while relevant and necessary for an approved purpose and must be refreshed, restricted, or retired when a source becomes private, deleted, blocked, age-restricted, disputed, or unavailable. A failed refresh guardrail prevents new restricted data but does not by itself clean up an older snapshot.
Today, removing a competitor from one workspace can soft-delete that workspace's competitor, attempt to remove eligible normalized records and canvas references, and enqueue Qdrant cleanup. Shared references can preserve some records. This tenant-scoped action is not the global non-user rights-removal process described below and does not immediately remove every matching raw artifact.
Private, deleted, blocked, and child-related profiles
Coul's collection guardrails reject provider records marked private, deleted, blocked, age-restricted, login-required, unavailable, or unauthorized and reject sensitive credential-like fields. If a formerly public source later enters one of those states, Coul must stop refresh and display, retire active records and derived memory, and preserve only bounded audit or suppression evidence where necessary.
Coul does not intentionally target children for competitor tracking or prediction research. The current product does not include reliable age classification or a known-minor suppression system, so before launch Coul must block a known child's profile, provide an expedited parent or guardian route, remove data when actual knowledge arises, and avoid derived strategies or embeddings from a known child's biography or captions.
Coul does not infer age from a face. A public adult-owned account can still feature a child or reveal information about a child or another vulnerable person; those records require contextual review rather than assuming the account owner's age resolves every concern.
Access, correction, objection, and removal
Depending on applicable law, a person may ask what public-profile data Coul holds about them, its sources and categories, recipients, purposes and inferences; request a copy or correction; object to or restrict processing; seek deletion or removal; appeal a refusal; and complain to a regulator. A non-user must not need a Coul account to make the request.
The Data Rights page will identify the active channel, verification, timing, exceptions, status, and appeal route. Before public launch, Coul must activate and test a monitored intake that acknowledges and tracks both user and non-user requests. The present administrator deletion machinery and a static notice do not provide that workflow.
A valid request must pause new refreshes while reviewed and search across tenants, trends, profile analyses, normalized profiles and posts, snapshots, media, raw artifacts, derived summaries, Qdrant vectors, caches, pending jobs, and provider copies. Coul must delete, restrict, correct, or isolate records as law and source obligations require and explain any bounded exception.
Verification and preventing re-import
Coul verifies requests proportionately. Depending on the risk, verification may use a control challenge through the source profile, confirmation through publicly listed creator contact details, proof of authority for an agent, or minimal evidence for a changed handle, deleted account, impersonation, guardianship, estate, or dissolved brand. Coul should avoid government identification unless genuinely necessary and promptly delete verification evidence when no longer needed.
After a valid objection or removal, Coul must store only the minimum suppression record needed to prevent routine re-import. A robust key can include platform, stable external identifier when available, normalized handle, known prior handles, and canonical source URLs; a handle alone can fail after rename or reassignment.
A suppression record is personal data. It requires limited purpose, restricted access, security, an approved retention rule, and a verified reversal process if the same creator later asks to connect their own profile. The workflow must test that scheduled jobs and a user re-adding the source cannot silently recreate removed records.
Copyright, impersonation, and platform complaints
A privacy or public-data objection and a copyright takedown are separate requests. A profile owner may raise both. Copyright complaints about stored thumbnails, captions, media references, templates, or copied output should use the Copyright/DMCA Policy; privacy, correction, source, or profiling concerns should use the Data Rights route.
Coul should prefer source links, approved embeds, factual metrics, and high-level summaries over storing full media where those methods meet the purpose. Thumbnails, captions, cached media, database extraction, publicity rights, trademarks, and systematic extraction require separate rights review even if an individual fact is not copyrightable.
Report impersonation, a reassigned handle, a misleading affiliation, or a source-platform deletion through the applicable rights route. Coul may restrict display while investigating and should preserve provenance without treating a badge, name, or avatar as conclusive identity proof.
Indirect notice and regional obligations
Where GDPR or UK GDPR applies, obtaining personal data from a public source and generating inferences can trigger indirect-notice duties. Coul must provide required information within the applicable period unless it documents a valid exception. A disproportionate-effort exception is not automatic merely because a profile was public, and publishing this notice is a safeguard rather than always a complete substitute for direct notice.
Coul must assess whether its business model makes it a data broker or another regulated data intermediary in California or elsewhere. Paid access to non-user profiles or derived inferences can trigger registration, disclosure, deletion, or suppression duties depending on the jurisdiction and available exclusions. Coul does not claim that it is or is not a data broker until that assessment is complete.
Where a rights request is denied or limited, Coul will explain the applicable reason and appeal route where required. People may also complain to their local privacy, data-protection, or consumer authority.
Pre-launch controls, changes, and contact
Before public-data features launch, Coul must verify the operator identity and contact; source-platform and dataset rights; Bright Data and Gemini terms, locations, retention, and deletion controls; deployed infrastructure; field inventory; direct-notice strategy; legitimate-interest and DPIA analysis; data-broker status; normalized and derived retention; global removal and suppression; child/guardian handling; and provider propagation.
Coul may update this notice when platforms, providers, fields, purposes, AI use, retention, or law changes. A materially different purpose or training use receives advance notice and any required legal basis or choice. Loss of source permission can require immediate suspension or removal rather than waiting for the next notice update.
The /data-rights page explains user and non-user request options but must not be described as an active tracked channel until the monitored workflow is live. For general questions, email privacy@coul.app only after Coul verifies the mailbox is monitored. Do not email passwords, access tokens, government identification, or confidential media unless Coul supplies a secure request method.
Contact
Is your profile shown in Coul?
The Data Rights page explains source, correction, objection, and removal options. Before launch, Coul must activate a monitored user and non-user intake; for a general privacy question, contact the privacy team without emailing identity documents or confidential media.